Re: Supporting sudoUser:!foo in sudo.ldap
"Michael Felt" <[email protected]> Tue, 14 Dec 2021 10:47:21 -0700
| Newsgroups | gmane.comp.tools.sudo.devel |
|---|---|
| Message-ID | <[email protected]> |
If you mean add a ! (not) operator, and that it should apply to any combination of any label now used to construct access control logic - imho, that make perfect sense. Stronger, I would think it was a bug when the others did not work. Regards, Michael -----Original Message----- From: sudo-workers <[email protected]> On Behalf Of Todd C. Miller Sent: Tuesday, 14 December 2021 08:56 To: Simon Lees <[email protected]> Cc: [email protected] Subject: Re: [sudo-workers] Supporting sudoUser:!foo in sudo.ldap I think this is worth pursuing. The question I have is whether supporting !username is sufficient. If we are going to support this kind of construct, it should probably mirror the existing query that contains uid, groups, gids and netgroups. Does that make sense? - todd ____________________________________________________________ sudo-workers mailing list <[email protected]> For list information, options, or to unsubscribe, visit: https://www.sudo.ws/mailman/listinfo/sudo-workers ____________________________________________________________ sudo-workers mailing list <[email protected]> For list information, options, or to unsubscribe, visit: https://www.sudo.ws/mailman/listinfo/sudo-workers